What a readiness assessment is for
The term is used loosely. In its useful sense, a readiness assessment is a targeted diagnostic exercise designed around a clear diagnostic objective. If the firm's principal supervisor reviewed the framework tomorrow, where would the evidence be strongest, where would it come under pressure and what do we need to understand before external scrutiny exposes it for us?
A readiness assessment may sit alongside Internal Audit, Compliance Monitoring, external assurance or annual AML and CFT reporting. The difference is purpose. Readiness is a targeted diagnostic against likely pressure points. It is not a substitute for Internal Audit, Compliance Monitoring or Independent Assurance. The testing techniques described in Perspective 005 are useful examples of the kinds of supervisory pressure a firm may face.
A maturity score can be useful context. I would not let it substitute for evidence. A firm can score itself as developed and still have a file sample that tells a very different story. A readiness assessment is intentionally uncomfortable. Its purpose is to identify, quickly and honestly, where the firm would come under pressure if scrutiny began next week.
Getting the scope right
Get the scope wrong and the assessment weakens quickly. Trying to cover the whole framework by default usually weakens the assessment. For a smaller or tightly scoped business, a broader review may still be proportionate. The scope should follow the risk, not a template.
Four areas frequently deserve attention in the firms I work with:
Sanctions, adverse media, SAR quality and specific product or channel risks may be added to scope where the firm's risk profile warrants it. The BWRA should inform the scope, alongside known weaknesses, regulatory commitments and the specific diagnostic objective. What rarely helps is a comprehensive review of every element of the framework by default, particularly where the risk points somewhere more specific.
The evidence base
A readiness assessment concludes on the evidence it gathered. Its credibility rises and falls on that evidence.
Interviews and document review are necessary but not sufficient. They tell the assessor what the framework believes about itself. The assessment needs evidence that can challenge the firm's own narrative. Depending on the control, that may mean file sampling, data analysis, process walkthroughs, governance records, system evidence or MI review. The method should follow the risk being tested.
Where file sampling is relevant, I would build the sample around the population and the risk rather than a fixed number. The sample needs enough coverage to test the question being asked, with deliberate representation of the cohorts most likely to expose weakness. For some smaller firms the appropriate sample may be relatively small. The number should follow the scope, population and question being tested. Where operational judgement is material to the assessment, I often want to observe the relevant forum rather than rely only on its minutes. I also want a structured MI walk-through with a member of executive or Board management, testing whether the pack gives governance enough information to understand, challenge, decide and follow up.
Reporting the results
Good fieldwork can still fail to produce change if the reporting is weak. The most rigorous sampling can be diluted into inaction by a report that softens findings, buries recommendations or presents the framework as more defensible than the evidence supports.
The report should be as short as the evidence allows. It opens with a plain-language statement of the firm's current readiness position and the specific items likely to come under pressure. It should distinguish what requires management-body understanding or challenge, what needs a governance decision and what belongs in operational remediation. It attaches evidence, either as anonymised file excerpts or as MI extracts, that supports the material findings.
The report should reach the governance forum with authority over the material issues, in many firms the Audit or Risk Committee, alongside the executive response. The response should itself be brief, name accountable owners and specify the evidence that will demonstrate closure. Where there is a substantive disagreement about a material finding, the disagreement, supporting evidence and governance outcome should remain visible in the record.
Common failure modes
When readiness assessments fail to produce useful change, the failure modes are usually recognisable.
Scope inflation dilutes conclusions. Framing as reassurance produces a report designed to comfort rather than to challenge. Excessive reliance on interviews produces conclusions that reflect what the framework believes about itself. Softening for the executive audience produces action plans that never quite land on individual owners. RAG status is useful only if the colour sits on top of evidence. A green box without the closure evidence underneath it tells the Committee very little.
None of these failures is caused by bad faith. Each is caused by design choices made early and adjusted too late. Naming them explicitly at scoping makes them much harder to ignore later.
How Claritas approaches readiness assessments
A Claritas readiness assessment is designed around the diagnostic objective above: where the evidence would be strongest, where it would come under pressure and what the firm needs to understand first. That framing shapes every design decision that follows.
Scope is agreed against the firm's risk assessment, known weaknesses, regulatory commitments and the specific diagnostic objective, and stays as narrow as the risk allows. The assessment is evidence-led. Where customer or case decisions are material, files become a central part of that evidence; elsewhere the evidence may sit in data, systems, governance records or control testing. The reporting route is agreed at the outset with the governance sponsor, so material findings reach the right forum without being diluted on the way.
For many smaller firms, a focused assessment can often be delivered over weeks rather than months. The exact duration should follow the scope and the evidence needed. Its purpose is to give the Board a credible diagnostic baseline and a specific runway of improvements. It is not designed to accumulate on a shelf.
- 01The Board holds an honest, current view of the firm's readiness position, with specific material weaknesses identified, owned and placed on a clear remediation timetable.
- 02The remediation runway is sequenced by materiality and executable within the firm's available capacity and any relevant regulatory commitments.
- 03The MI pack gives accountable senior leaders enough information to explain the firm's principal risks, material control weaknesses and the actions being taken.
- 04Readiness is maintained through the firm's normal governance, assurance and remediation cycle rather than recreated only when supervisory pressure appears.
- 05The governance record shows that material findings produced visible challenge, action or decision where needed, and that the resulting change can be evidenced.
- Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering or terrorist financing: internal policies, procedures and controls, and internal audit. eur-lex.europa.eu/eli/reg/2024/1624/oj
- Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA). eur-lex.europa.eu/eli/reg/2024/1620/oj
- European Banking Authority, Risk-Based Supervision Guidelines (EBA/GL/2021/16), applicable until replaced or superseded.
- SEPBLAC, Memoria 2025 (annual report, published June 2026). www.sepblac.es/wp-content/uploads/2026/06/MemoriaSepblac2025_ES.pdf
- Central Bank of Ireland, Anti-Money Laundering Supervisory Priorities. www.centralbank.ie/regulation/anti-money-laundering-and-countering-the-financing-of-terrorism
- UK comparator: Financial Conduct Authority, Financial Crime Guide. www.handbook.fca.org.uk/handbook/FCG.pdf
- European Banking Authority, Guidelines on Policies and Controls for the Effective Management of ML/TF Risks (EBA/GL/2022/05).



